Privacy Policy

Last updated: July 2026

1. Introduction

FlowConfig ("we", "us", "our") operates the FlowConfig platform, including the web dashboard at app.flowconfig.site, the FlowConfig Flutter SDK published on pub.dev, and the FlowConfig CLI. This Privacy Policy explains how we collect, use, and protect your information when you use our services.


2. Information We Collect

Account Information:

When you create a FlowConfig account, we collect your name, email address, and password (hashed). If you sign up via Google OAuth, we receive your name and email from Google.

Organization & Project Data:

We store the projects, configurations, feature flags, and other data you create within FlowConfig. This data belongs to you and is used only to provide the service.

SDK Analytics Data (Anonymous):

The FlowConfig Flutter SDK collects anonymous usage data to power your analytics dashboard. This includes:

  • Hashed device identifiers (cannot be reversed to identify a device)
  • App version and SDK version
  • Platform (iOS or Android)
  • Anonymous event types (app launch, config fetch, flag evaluation)

We do NOT collect:

  • User names or emails from your end users
  • Location data
  • Personally identifiable information from SDK events
  • Payment card details (handled by LemonSqueezy)

Usage Data:

We collect standard server logs including IP addresses, browser type, and pages visited on our dashboard. These logs are retained for 30 days for security purposes.


3. How We Use Your Information

  • To provide and operate the FlowConfig service
  • To send transactional emails (invitation, billing receipts)
  • To display analytics in your dashboard
  • To enforce plan limits and billing
  • To respond to support requests
  • To improve the platform based on usage patterns

We do not sell your data to third parties.

We do not use your data for advertising purposes.


4. Data Retention

  • Account data: retained while your account is active
  • Analytics events: 90 days
  • Activity logs: 1 year
  • Audit logs: 2 years
  • SDK error logs: 30 days
  • Release snapshots: until manually deleted
  • After account deletion: all data removed within 30 days

5. Third-Party Services

We use the following third-party services:

  • Supabase (supabase.com) — Database and authentication
  • Vercel (vercel.com) — Hosting and edge functions
  • LemonSqueezy (lemonsqueezy.com) - Payment processing and billing
  • Resend (resend.com) — Transactional email delivery

Each service has its own privacy policy. We share only the minimum data necessary for each service to function.


6. Cookies

We use essential cookies only:

  • Authentication session cookie (required to stay logged in)
  • Preference cookies (theme, sidebar state)

We do not use advertising or tracking cookies.


7. Your Rights

You have the right to:

  • Access the data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and data
  • Export your configuration data
  • Withdraw consent at any time

To exercise these rights, email: privacy@flowconfig.site


8. Data Security

We implement industry-standard security measures:

  • All data encrypted in transit (HTTPS/TLS)
  • Database encrypted at rest
  • Row-level security on all database tables
  • Regular security audits
  • No sensitive keys stored in client-side code

9. Children's Privacy

FlowConfig is not intended for use by anyone under 16 years of age. We do not knowingly collect data from children.


10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice in the dashboard. Continued use of FlowConfig after changes constitutes acceptance of the updated policy.


11. Contact

For privacy-related questions:

Email: privacy@flowconfig.site
Company: FlowConfig